Configure the following event notification to notify administrators when Deep Discovery Email Inspector detects malicious or suspicious email messages or attachments sent to watchlisted recipients.
- 
                Go to Detections > Notifications > Event Notifications.
                 
                    The Event Notifications screen appears. 
- 
                Click Advanced Threat
                    Activity.
                 
                    A list of events appears. 
- 
                In the Event column, click
                        Watchlisted recipients at risk.
                 
                    The Watchlisted Recipients at Risk screen appears. 
- 
                Specify the following notification settings.
                 
                    
Criteria Description Email address watchlist Type the email addresses to be monitored. Use a semicolon (;) to separate multiple entries. Type Select the risk level of the detections that trigger the event notification. Detections Type the number of threats detected by the managed product. Period Specify the time period for the detections. 
- 
                Select recipients for the notification.
                - From the Available Users and Groups list, select contact groups or user accounts.
- 
                        Click >.
                         
                            The selected contact groups or user accounts appear in the Selected Users and Groups list. 
 
- 
                Enable one or more of the following notification methods.
                 
                    
Method Description Email message To customize the email notification template, use supported token variables or modify the text in the Subject and Message fields. For more information, see Standard Token Variables and Advanced Threat Activity Token Variables. 
- To test if recipients can receive the event notification, click Test.
- Click Save.
 
		